CVE-2016-2567
3.3
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Exploitability: 1.8 / Impact: 1.4
Source: NVD
Description
secfilter in the Samsung kernel for Android on SM-N9005 build N9005XXUGBOB6 (Note 3) and SM-G920F build G920FXXU2COH2 (Galaxy S6) devices allows attackers to bypass URL filtering by inserting an "exceptional URL" in the query string, as demonstrated by the http://should-have-been-filtered.example.com/?http://google.com URL.
Affected (2)
Products: Samsung: Galaxy S6 Firmware, Galaxy Note 3 Firmware
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version g920fxxu2coh2 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy S6 | All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version n9005xxugbob6 |
| Running on/with | Platform Versions |
|---|---|
Samsung Galaxy Note 3 | All versions |
References (2)
Source: cve@mitre.org
ExploitTechnical DescriptionThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitTechnical DescriptionThird Party Advisory
Timeline
No history available yet.